VDAI (Lithuania) - 3R-830
| VDAI - 3R-830 | |
|---|---|
| [[File:|center|250px]] | |
| Authority: | VDAI (Lithuania) |
| Jurisdiction: | Lithuania |
| Relevant Law: | Article 5(1)(c) GDPR Article 14(1) GDPR Article 14(2) GDPR Article 14(3)(a) GDPR Article 14(3)(b) GDPR Article 28(3) GDPR |
| Type: | Complaint |
| Outcome: | Partly Upheld |
| Started: | 09.10.2025 |
| Decided: | 08.05.2026 |
| Published: | |
| Fine: | n/a |
| Parties: | Lietuvos draudimas |
| National Case Number/Name: | 3R-830 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Lithuanian |
| Original Source: | VDAI (in LT) |
| Initial Contributor: | ap |
The DPA found that an insurance company had not provided a data subject with information required under Articles 14 GDPR within the statutory timeframe. However, the DPA considered that the data subject could not object to the company transferring data related to their debt to their processor, a debt collection agency.
English Summary
Facts
Lietuvos draudimas (the controller) is an insurance company. In 2025, a data subject filed a complaint with the DPA. According to the data subject, the controller transferred their personal data to a third party without establishing liability for damages. The controller also failed to provide information in accordance with Article 14 GDPR, and processed data to an excessive extent.
During its investigations, the DPA found that the controller obtained data from third parties during insurance proceedings in order to identify the data subject; this includes the state company registry and a third person affected by the data subject. The controller later transferred the data subject’s data to a debt collection agency (the processor) after the data subject failed to pay the controller within the time limit.
Holding
The DPA first clarified that it was not competent to examine the parties’ insurance rights, and that this case was limited to verifying the lawfulness of the processing activities. The DPA partially upheld the data subject’s claim.
The DPA found a violation of Articles 14(3)(a) and (b) GDPR, as the controller provided the data subject with information required under Articles 14(1) and (2) GDPR late. The controller received data from third parties regarding the data subject, therefore, it should have provided this information without undue delay (and no later than upon first contact with the data subject). According to the DPA, the controller failed to do both.
However, the DPA did not find a violation of Article 28(3) GDPR. The DPA stated that the GDPR regulates the relationship between controllers and processors, and does not give the data subject the right to object to (or authorise) a controller transferring data to a processor. The DPA also dismissed the data subject’s data minimisation claim. The DPA found that the controller processed the necessary data in the debt collection proceedings; if the controller limited the data processed (e.g. to first and last name only) it would not be able to accurately identify the data subject or provide the processor with information related to the data subject’s debts. Therefore, the DPA did not find a violation of Article 5(1)(c) GDPR.
The DPA did not issue any fines or enforcement measures, as it considered that acknowledging the violation was sufficient. The controller fulfilled its information obligations under Articles 14(1) and (2) GDPR, even if it was provided late. In addition, the DPA considered that the controller’s actions did not cause significant negative consequences for the data subject.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Lithuanian original. Please refer to the Lithuanian original for more details.
Extract of an electronic document STATE DATA PROTECTION INSPECTORATE DECISION 2026 m. May 8. No. 3R-830 (2.13-1.E) Vilnius The State Data Protection Inspectorate (hereinafter – the Inspectorate) on 2025-10-09 received a complaint from [DATA NOT PUBLISHED] (hereinafter – the Applicant) (Inspection reg. No. 1R-6821 (2.13 Mr)) (hereinafter – complaint) regarding the actions of AB “Lietuvos draudimas” (hereinafter – the Complainant, the Company). The complaint states that the Company transferred the Applicant’s personal data to a third party [DATA NOT PUBLISHED] in the absence of proven liability for the damage. In the Applicant’s assessment, such actions of the Complainant violate the provisions of the GDPR1. The Complainant also failed to provide information in accordance with the provisions of Article 14 of the GDPR and processed the Applicant's personal data to a disproportionate extent. The Inspectorate, having examined the Applicant's complaint within its scope, determined: On 2025-11-03 the Inspectorate received the Complainant's explanation (Inspection reg. No. 1R-7518 (2.13 Mr)) and on 2026-01-14 it received an additional explanation from the Complainant (Inspection reg. No. 1R-280 (2.13 Mr)) (hereinafter referred to together as the Complainant's explanation), which stated that the dwelling located at [DATA NOT PUBLISHED] was damaged on 2024-10-21 and 2025-03-05. This dwelling was insured by the Complainant. The Company, in accordance with the terms of the housing insurance contract, compensated the policyholder for the damage suffered during the insured events, therefore it acquired the right to recover the compensated damage from the person responsible for the damage. The Company's experts, in accordance with the requirements of legal acts obliging them to investigate the circumstances of the insured event, based on the information collected from the owner of the affected apartment, the flooding photos, and the layout of the premises, determined that the affected apartment was flooded from the upper apartment, i.e. from the apartment located at [DATA NOT PUBLISHED]. The Complainant, in order to find out the owner of this apartment and his declared place of residence in order to be able to exercise the right of recourse established in legal acts, received the data of the owner of this apartment (the Applicant) from the State Enterprise Register Centre on 29-10-2024 and 14-03-2025. The Complainant also states that the Company received the Applicant's phone number from the owner of the affected apartment on 20-05- 2025. The Complainant indicates that the Applicant did not reimburse the insurance benefit paid by the Company to the owner of the apartment [DATA NOT PUBLISHED] within the time limits specified by him, therefore the Company transferred the pre-trial debt recovery and the Applicant's data necessary for debt recovery to the debt collection company [DATA NOT PUBLISHED]. It is the data processor used by the Complainant, which acts on behalf of the Company when carrying out debt recovery. [DATA NOT PUBLISHED] the Applicant's name, surname, personal identification number, address, and amount of debt were transferred. The aforementioned 1 2016 m. April 27 d. Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as the GDPR). 2 The applicant's data, in order to implement the requirements of the GDPR, were transferred on the basis of contracts concluded between the data controller and the data processor. Due to the damage caused on 21-10-2024 by [DATA NOT PUBLISHED], the Applicant's personal data were transferred to the housing company on 2025-01-06, in accordance with the Company's personal data processing agreement with [DATA NOT PUBLISHED] (from [DATA NOT PUBLISHED]). Due to the damage caused to the same dwelling on 05-03-2025, the Applicant's personal data was transferred on 05-06-2025, based on the personal data processing agreement between the Company and [DATA NOT PUBLISHED], which is valid from 28-03-2025 (hereinafter referred to as the Agreement2). The explanation of the Complainant states that the Applicant was informed in accordance with the requirements of Article 14 of the GDPR and within the deadlines set by the GDPR for exercising the aforementioned right. The Company, having received the Applicant's data from the State Enterprise Registers Centre on 29-10-2024 and 14-03-2025, provided him with letter No. R0004197815 on 29-10-2024 and letter No. R0004397833 on 14-03-2025, which indicated the information established in Article 14 of the GDPR. The data processor used by the Complainant [DATA NOT PUBLISHED] 2025-01-16 by letter No. R0004197815, 2025-02-06 by letter No. R0004197815, 2025-03-10 by letter No. R0004197815, 2025-06-12 by letter No. R0004397833, 2025-07-04 by letter No. R0004397833, 2025-08-13 by letter No. R0004397833 also provided the Applicant with information pursuant to Article 14 of the GDPR. Regarding the proportionality of the volume of data processed by the Company, the Complainant indicates that it is necessary for him to process the Applicant's contact details (telephone number, address) in order to contact the Applicant regarding debt collection issues. Regarding the limits of the Inspectorate's competence, the Applicant claims in the complaint that it has not been proven that he is (was) indebted to the Complainant. The Complainant, in turn, indicated the circumstances and submitted related evidence, which support the fact that insured events occurred on 2024-10-21 and 2025-03-05, - the owner of the apartment at the address [DATA NOT PUBLISHED] (the Applicant) damaged the insured housing at the address [DATA NOT PUBLISHED]. The Company to the insurer, i.e. [DATA NOT PUBLISHED], the owner, compensated for the damage suffered during the insured events and acquired the right to the refund of the paid amounts from the Applicant. Sub-clause 9.2 of the Regulations of the State Data Protection Inspectorate2 (hereinafter referred to as the Regulations) enshrines one of the objectives of the Inspectorate's activities - to monitor and ensure the application of the GDPR, the Law on the Legal Protection of Personal Data Processed for the Prevention, Investigation, Detection or Prosecution of Criminal Offences, the Execution of Sentences or for National Security or Defence Purposes (hereinafter referred to as the Law on the Legal Protection of Personal Data), the Law of the Republic of Lithuania on the Legal Protection of Personal Data (hereinafter referred to as the Law on the Legal Protection of Personal Data), except for cases where this is within the competence of the Inspector of Journalist Ethics, and to supervise and control the implementation of the provisions of the Law on Electronic Communications of the Republic of Lithuania regulating the processing of personal data and the protection of privacy. In order to achieve the objective specified in Sub-clause 9.2 of the Regulations, the Inspectorate, inter alia, shall examine complaints of individuals in accordance with the procedure established by the GDPR, the Personal Data Protection Authority, and the Law Enforcement Personal Data Protection Authority in cases established by the provisions of these laws and the Law on Electronic Communications regulating the processing of personal data and the protection of privacy, and shall examine complaints of individuals in cases established by international agreements in accordance with the procedure established by the Inspectorate and, based on the information provided in the complaints, shall verify the lawfulness of the processing of personal data and shall make decisions on violations of the processing of personal data (Sub-clause 11.1 of the Regulations). Article 6.1015 of the Civil Code of the Republic of Lithuania establishes that the insurer who has paid an insurance benefit shall be entitled to claim the amounts paid from the person responsible for the damage caused. 2 Regulations of the State Data Protection Inspectorate, approved by Resolution No. 25 of the Government of the Republic of Lithuania of 25 September 2001 of the Government of the Republic of Lithuania 1156 “On the Approval of the Regulations of the State Data Protection Inspectorate”. 3 Therefore, the activities of the Inspectorate, as a supervisory authority, in examining complaints of individuals are related to the verification of the legality of personal data processing within the scope of the complaint examination, however, the Inspectorate is not granted the authority to resolve issues related to the transfer of the policyholder’s rights to compensation for damage to the insurer (subrogation). Taking into account the above-discussed legal regulation and the information provided by the parties, the Inspectorate in the case under consideration, within the scope of its competence and the legal regulation established by the GDPR, only speaks about the legality of the actions of the Complainant in transferring the Applicant’s personal data to a debt collection company, the right to receive information about data processing and the possible violation of the principle of data minimization. Regarding the transfer of personal data, the processing of personal data is regulated by the GDPR and the ADTAĮ. According to Article 4(7) of the GDPR, a data controller is a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. According to Article 4(8) of the GDPR, a data processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller. The data controller may process the data itself and/or authorise the data processor. The GDPR does not provide for the right of the data subject to object to the data controller transferring his or her personal data to the data processor, nor does it provide for any circumstances under which the data controller may not authorise the data processor to process the data; on the contrary, the GDPR regulates the relationship between the data controller and the data processor (Chapter IV of the GDPR). Article 28(3) of the GDPR provides that the processing of data by the data processor shall be governed by a contract or another legal act. Based on the circumstances indicated in the Complainant's explanation, it has been established that the Applicant's personal data was transferred to [DATA NOT PUBLISHED] on 06/01/2025 under Agreement13, which was valid from 28/04/2020 to 27/03/2025, and on 05/06/2025 the Applicant's personal data was transferred to [DATA NOT PUBLISHED] under Agreement2, which was valid from 28/03/2025. The Complainant submitted to the Inspectorate the Legal Services Agreement1 and Agreement2 concluded between him and [DATA NOT PUBLISHED], which clearly define and provide for the rights and obligations of the parties to the aforementioned agreements in the context of personal data processing, as established by Article 28(3) of the GDPR. The specified documents define that the Complainant acts as a data controller, and [DATA NOT PUBLISHED] acts as a data processor. Taking into account the provisions of Agreement1, Agreement2, the Inspectorate has determined that a data controller and data processor relationship has been established between the Complainant and [DATA NOT PUBLISHED], therefore [DATA NOT PUBLISHED] has the right to carry out debt collection on behalf of the Complainant and to process personal data accordingly. Based on the above and the fact that the GDPR does not provide for the right of the data subject to object to the data controller transferring his or her personal data to the data processor, and does not provide for any circumstances due to which the data controller cannot authorize the data processor to process the data, it is concluded that the Complainant transferred the Applicant's personal data to [DATA NOT PUBLISHED] lawfully. No violations of the ADTAĮ and GDPR have been identified in the actions of the Complainant, therefore the Applicant's complaint in this part is rejected. On the violation of Article 14(3)(a) and (b) of the GDPR The Applicant complains that the Complainant did not provide all the information in accordance with Article 14(1) and (2) of the GDPR. 3 The Agreement1 was concluded between the Complainant and [DATA NOT PUBLISHED]. According to the data of the State Enterprise Register Centre, the name of [DATA NOT PUBLISHED] has been changed to [DATA NOT PUBLISHED]. 4 Article 14(1) of the GDPR provides that where personal data are not obtained from the data subject, the data controller shall provide the data subject with the following information: the identity and contact details of the data controller and, if applicable, the data controller’s representative; the contact details of the data protection officer, if applicable; the purposes of the data processing for which the personal data are intended to be processed, as well as the legal basis for the processing; the categories of personal data concerned; and, if any, the recipients or categories of recipients of personal data. In accordance with Article 14(2) of the GDPR, in addition to the information referred to in paragraph 1, the controller shall provide the data subject with the following additional information necessary to ensure the fairness and transparency of the processing in relation to the data subject: the period for which the personal data will be stored or, where that is not possible, the criteria for determining that period; where the processing is carried out on the basis of Article 6(1)(f) of the GDPR, the legitimate interests pursued by the controller or by a third party; the right to request that the controller provide access to and rectify or erase the personal data concerning the data subject, or to restrict processing, and the right to object to processing, as well as the right to data portability; the right to lodge a complaint with a supervisory authority; the origin of the personal data. In accordance with Article 14(3)(a) and (b) of the GDPR, the controller shall provide the information referred to in paragraphs 1 and 2 of this Article: within a reasonable period of time from the receipt of the personal data, but not later than one month, taking into account the specific circumstances of the processing of the personal data; where the personal data will be used to communicate with the data subject, not later than the first communication with that data subject. WP 260 of 2018-04-11 on transparency under Regulation 2016/679 (hereinafter referred to as the WP 260 Guidelines) provides in paragraph 27 that, where personal data are indirectly received pursuant to Article 14, the general requirement is that the information shall be provided within a “reasonable period” of time from the receipt of the personal data, but not later than one month. The general period of one month set out in Article 14(3)(a) of the GDPR may be shortened in accordance with Article 14(3)(b) of the GDPR if the personal data are used to maintain contact with the data subject. In such a case, the information must be provided no later than the first time the data subject is contacted. Based on the data provided in the Complainant's explanation, it has been established that after the insured events occurred on 21 October 2024 and 5 March 2025, in order to recover the debts incurred during them, the Complainant received the Applicant's personal data from the State Enterprise Register Centre on 29 October 2024 and 14 March 2025. The Complainant also received the Applicant's telephone number from the injured apartment owner on 20 May 2025 for the purpose of recovering the debts incurred during the insured event on 21 October 2024. Accordingly, in accordance with Article 14(3)(a) and (b) of the GDPR, point 27 of the Guidelines WP 260, the Applicant should have been provided with the information specified in Article 14(1), (2) of the GDPR, when processing data received from the State Enterprise Registers Centre, without undue delay by 2024-11-29 and 2025-04-14, and no later than when first contacting the Applicant. The source of origin of the Applicant's telephone number should have been indicated by 2025-06-20. Having assessed the complaint materials, the Inspectorate established that the Complainant, while processing the Applicant's personal data, obtained not from the Applicant, for the purpose of recovering debts incurred during the insured events of 2024-10-21 and 2025-03-05, provided the Applicant with information in accordance with Article 14, paragraph 1, point d, paragraphs 2, c, e of the GDPR on 2025-01-16 and 2025-06-12, and the information specified in paragraph f of this paragraph about the source of origin of the personal data (the State Enterprise Centre of Registers and the owner of the victim's apartment) was provided on 2025-09-254. In this way, the Complainant did not comply with the requirements of Article 14, paragraph 3, points a and b of the GDPR, since the aforementioned information was provided late and not for the first time after contacting the Applicant5. Taking into account the above, in this case the Inspectorate states, 4 Other information specified in Article 14, paragraphs 1, 2 of the GDPR was provided to the Applicant in accordance with the requirements of Article 14, paragraph 3, points a, b of the GDPR. 5 For the first time on 2024-10-21 for the purpose of recovering the debt incurred during the insured event, the Complainant contacted the Applicant by letter No. R0004197815 dated 2024-10-29, and for the first time on 2025-03-05 for the purpose of recovering the debt incurred during the insured event, the Complainant contacted the Applicant by letter No. R0004397833 dated 2025-03-14. 5 that the Complainant has violated Article 14(3)(a) and (b) of the GDPR and the Complainant's complaint is hereby recognized as justified. Regarding the violation of the data minimization principle The Complainant indicated in the complaint that the Complainant processed his personal data in a disproportionate manner. Taking into account the above, the Inspectorate assesses that the Complainant is complaining about a violation of the data minimization principle established in Article 5(1)(c) of the GDPR. Article 5(1)(c) of the GDPR establishes that personal data must be adequate, relevant and not excessive in relation to the purposes for which they are processed (data minimization principle). From the Respondent's response to the Applicant dated 25 September 2025, it can be seen that the Respondent processes the Applicant's name, surname, personal identification number, date of birth, address, telephone number and the circumstances of the occurrence and amount of the specified debts in order to recover the debts. In the opinion of the Inspectorate, processing the above-mentioned personal data of the Applicant is necessary for the Respondent in matters of debt recovery. In the opinion of the Inspectorate, processing of a narrower scope of the Applicant's data, for example, only the name and surname, would not ensure proper and accurate identification of the data subject (the Applicant) and information on the issues of the aforementioned debts. Taking into account the above and the above-mentioned legal regulation, the Inspectorate finds that there is no reason to conclude that the processing of the Applicant's personal data (name, surname, personal identification number, date of birth, address, telephone number and circumstances of the occurrence and amount of the debt) would violate the principle of data minimization established in Article 5(1)(c) of the GDPR. The Applicant's complaint in this part is rejected as unfounded. Regarding the application of enforcement measures Paragraph 129 of the GDPR provides that each measure applied by the supervisory authority must be appropriate, necessary and proportionate in order to ensure compliance with this Regulation, taking into account the circumstances of each specific case. Article 31(2) of the Act on the Protection of Personal Data provides that when a complaint or part thereof is recognized as justified, the Inspectorate shall provide the data controller and/or data processor with instructions, recommendations and/or apply other measures specified in the legal acts regulating the protection of personal data and/or privacy. The European Court of Human Rights, in defending the fundamental human rights and freedoms enshrined in the European Convention for the Protection of Human Rights and Fundamental Freedoms, often states that the mere recognition of a violation of a right is sufficient and fair satisfaction in itself to protect the violated right. The Supreme Administrative Court of Lithuania (hereinafter referred to as the LVAT) also follows this practice (e.g. LVAT 2019-10-16 ruling in administrative case No. A-1156-822/2019). It should be noted that the ADTAĮ provides for the Inspectorate's discretionary right to select corrective measures, after recognizing the complaint as justified, it is only important that each measure applied by the Inspectorate is appropriate, necessary and proportionate, taking into account the violation. In the case under consideration, it was established that the Complainant, albeit belatedly, nevertheless implemented the Applicant's right to receive information, enshrined in Article 14, paragraphs 1 and 2 of the GDPR. In addition, the Inspectorate did not establish that these actions of the Complainant would have caused greater negative consequences for the Applicant. In the circumstances indicated, the Inspectorate decides that the recognition of the violation in this case is a sufficient measure to protect the Applicant's violated right, and the application of other measures of influence in this case would not comply with the principle of proportionality. 6 The Inspectorate, taking into account the above and in accordance with Article 31, Part 1, Points 1 and 2 of the ADTAĮ, decided: 1. To reject the Applicant's complaint in part regarding the violation of the principle of personal data transfer and data minimization . 2. To declare the Applicant's complaint in part regarding the violation of Article 14, Part 3, Points a and b of the GDPR founded. 3. To inform the Applicant and the Complainant about the decision taken. This decision may be appealed to the Regional Administrative Court (address: Žygimantų g. 2, Vilnius) within one month from the date of its service, in accordance with the procedure established by the Law on Administrative Procedure of the Republic of Lithuania. Deputy Director, acting as Director Danguolė Morkūnienė



